Showing posts with label digital forensics. Show all posts
Showing posts with label digital forensics. Show all posts

Friday, March 25, 2011

Virginia Law Signed Exempting Computer Forensics from Private Investigator Licensing

Bravo! to Sharon Nelson and company for getting this bill off the ground. This is HUGE for the forensics community, as several states have been requiring computer forensics professionals to obtain (an often impossible) Private Investigator's license to operate.

Summary of the bill as introduced: "Computer and digital forensic services; exempt from regulation as a private security service business. Exempts from regulation as a private security service business any individual engaged in (i) computer or digital forensic services or in the acquisition, review, or analysis of digital or computer-based information, whether for purposes of obtaining or furnishing information for evidentiary or other purposes or for providing expert testimony before a court, or (ii) network or system vulnerability testing, including network scans and risk assessment and analysis of computers connected to a network."

Thursday, March 24, 2011

Integrating Forensic Investigation Methodology into eDiscovery

I just came across a fantastic paper by Colin Chisholm and Jeff Groman, submitted as a GIAC Gold Certification paper to the SANS Institute in January 2010. As the title, Integrating Forensic Investigation Methodology into eDiscovery, would suggest, it lays out the implementation of forensic methodology to the eDiscovery process (limited to the Collection & Preservation phases of the EDRM). This paper is a great read for the three camps: Forensicators operating in the eDiscovery space, members of the legal community, and eDiscovery professionals who would benefit from some more insight into the mentality of traditional forensic investigators. It is extremely helpful for members of each group to understand the terminology, methodology, and (most importantly) the basis of thought of each of the other counterparts. This paper does a stellar job at bridging that gap.

Wednesday, October 13, 2010

The difference between e-Discovery and Computer Forensics?

Having come down the digital forensics track, it took me a while to come to grips with the idea of e-Discovery.  I remember thinking, "So let me get this straight... A write blocker is unnecessary and data in unallocated space is not important?"  While that is not always the case with e-discovery, it is more often than in a case calling for computer forensics.

It is important to differentiate whether an engagement calls for e-discovery or forensics from the beginning in order to establish goals and pricing.  For example, forensics work is generally billed by the hour, whereas e-discovery processing is often charged by the amount of data. It is also not uncommon for a typical e-discovery case to require forensics processes after, let's say, the initial e-discovery production seems to be missing emails expected to have been produced.

Yesterday, I read a fantastically concise explanation for differentiating e-discovery and computer forensics by Bill Dean at Sword & Sheild's blog. Our communities need articles like this to help bridge the verbiage gap between attorneys, litigation support personnel, and e-discovery and computer forensics practitioners.  I highly recommend spending five minutes to take a look.

Tuesday, July 20, 2010

Internet luring case in Canada finds 19-year-old man guilty

CBC News reported the guilty verdict of a 19-year-old man in Canada convicted of Internet luring involving a teenager.  This case went to the Supreme Court of Canada on the matter of whether the accused has to intend to meet the victim in order to be found guilty; the Court decided that the accused only has to make a meeting possible.

Article Link:  New Brunswick man guilty of internet luring

The Vancouver Sun reported on the Supreme Court's decision in May 2010, prior to the final ruling on the case.  This article looks a little closer at the considerations of the Court and the law that was the crux of consideration.

Article Link:  P.E.I. cyber-sex case to test Internet luring law (Vancouver Sun)

Tuesday, July 13, 2010

The Attorney/Forensic Examiner Language Barrier

I have spent much of my life explaining technical issues to less tech-savvy people, so I know first-hand how important it is.  As with most specializations, the mentality and language is simply different than how most people think and speak.  I know when I put on my general ledger thinking cap, the word debit has a different meaning than it does to most debit-card using consumers.  This article at the ExForensics blog explains and helps clarify some of the verbiage that is often misunderstood when a computer forensics type communicates with a member of the attorney or e-discovery party.  I highly recommend this article for both attorneys and computer forensics people.  At the very least, you need to know that some words (i.e. "copy") need clarification.

Article Link: Attorneys are from Mars, Computer Forensics People are from Pluto

Monday, July 12, 2010

Documenting both child and porn can delay cases

Gordon Dritschilo wrote an article that touches on some of the main issues law enforcement faces when investigating child pornography, including age determination, unintended downloads, file verification and backlogs.  The article was later discussed on the Cyberspeak podcast on April 4th, 2010.

Article Link: Documenting both child and porn can delay cases